<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best Practice for Alert Time Range and Cron Expression in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Best-Practice-for-Alert-Time-Range-and-Cron-Expression/m-p/455376#M8066</link>
    <description>&lt;P&gt;hello there&lt;/P&gt;

&lt;P&gt;will recommend to set a strict time window on your search and verify how long your search takes to complete&lt;BR /&gt;
maybe something like, earliest = -7m@m latest = -2m@m&lt;BR /&gt;
this will guarantee you will not miss an event&lt;/P&gt;

&lt;P&gt;hope it helps&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jul 2018 10:13:05 GMT</pubDate>
    <dc:creator>adonio</dc:creator>
    <dc:date>2018-07-25T10:13:05Z</dc:date>
    <item>
      <title>Best Practice for Alert Time Range and Cron Expression</title>
      <link>https://community.splunk.com/t5/Alerting/Best-Practice-for-Alert-Time-Range-and-Cron-Expression/m-p/455375#M8065</link>
      <description>&lt;P&gt;I'm setting up an alert that I want to run every five minutes so I set the cron expression like such "*/5 * * * *". If I set the time range to last five minutes is it possible that I could miss events? Does Splunk make sure that the two sync up? I assume it is possible that the cron iteration could be slightly off (drift) from the last iteration thus there could be a few seconds where the time range would not apply as the cron was not totally in sync for each iteration. And I correct in this assumption? If so what is the best way to do something like this?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 22:39:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Best-Practice-for-Alert-Time-Range-and-Cron-Expression/m-p/455375#M8065</guid>
      <dc:creator>dstuder</dc:creator>
      <dc:date>2018-07-24T22:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice for Alert Time Range and Cron Expression</title>
      <link>https://community.splunk.com/t5/Alerting/Best-Practice-for-Alert-Time-Range-and-Cron-Expression/m-p/455376#M8066</link>
      <description>&lt;P&gt;hello there&lt;/P&gt;

&lt;P&gt;will recommend to set a strict time window on your search and verify how long your search takes to complete&lt;BR /&gt;
maybe something like, earliest = -7m@m latest = -2m@m&lt;BR /&gt;
this will guarantee you will not miss an event&lt;/P&gt;

&lt;P&gt;hope it helps&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 10:13:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Best-Practice-for-Alert-Time-Range-and-Cron-Expression/m-p/455376#M8066</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-07-25T10:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice for Alert Time Range and Cron Expression</title>
      <link>https://community.splunk.com/t5/Alerting/Best-Practice-for-Alert-Time-Range-and-Cron-Expression/m-p/455377#M8067</link>
      <description>&lt;P&gt;Upvoted. That is also what I do. Use the snap-to which will ensure you cover what your brain intended.&lt;/P&gt;

&lt;P&gt;More details at: &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/SearchTimeModifiers#How_to_specify_relative_time_modifiers"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/SearchTimeModifiers#How_to_specify_relative_time_modifiers&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 13:00:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Best-Practice-for-Alert-Time-Range-and-Cron-Expression/m-p/455377#M8067</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2018-07-26T13:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice for Alert Time Range and Cron Expression</title>
      <link>https://community.splunk.com/t5/Alerting/Best-Practice-for-Alert-Time-Range-and-Cron-Expression/m-p/455378#M8068</link>
      <description>&lt;P&gt;Thinking about this a bit I think I would want to alert based on indexed time not event time. For instance my alert is pulling from Windows event logs. If an event happened matching the pattern and say the Splunk Forwarder was not running for more than five minutes when the event came in to the indexer I would not be alerted as earliest and latest are based on _time right? Should I then include the time range in the search string itself and base it on _indextime and set Time Range in the alert to All Time?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 19:31:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Best-Practice-for-Alert-Time-Range-and-Cron-Expression/m-p/455378#M8068</guid>
      <dc:creator>dstuder</dc:creator>
      <dc:date>2018-07-26T19:31:20Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice for Alert Time Range and Cron Expression</title>
      <link>https://community.splunk.com/t5/Alerting/Best-Practice-for-Alert-Time-Range-and-Cron-Expression/m-p/455379#M8069</link>
      <description>&lt;P&gt;Ok, maybe not setting it to "All time" now that I think about it (that's just crazy talk) but maybe sometime like last seven days or something.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 19:34:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Best-Practice-for-Alert-Time-Range-and-Cron-Expression/m-p/455379#M8069</guid>
      <dc:creator>dstuder</dc:creator>
      <dc:date>2018-07-26T19:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice for Alert Time Range and Cron Expression</title>
      <link>https://community.splunk.com/t5/Alerting/Best-Practice-for-Alert-Time-Range-and-Cron-Expression/m-p/455380#M8070</link>
      <description>&lt;P&gt;You're thinking about this all in a very healthy manner. Good job!&lt;/P&gt;

&lt;P&gt;Essentially, the data COULD come in delayed. You could use the difference between indextime and time to get confidence of the drift. If the drift in your environment is large, then you probably want to investigate that because such a large drift would unmine the confidence in any Splunk insight. But if the drift is manageable then you may feel confidence with setting the time selector to something like the last hour and using indextime to ensure you catch everything. Alternatively, if you know drift is, at most, a few minutes, then you could use the dynamic snap-to to run your search over a sufficiently long ago _time.&lt;/P&gt;

&lt;P&gt;I think I'm just articulating what you already knew though.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 12:34:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Best-Practice-for-Alert-Time-Range-and-Cron-Expression/m-p/455380#M8070</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2018-07-27T12:34:58Z</dc:date>
    </item>
  </channel>
</rss>

